Hello everybody,
lately we are noticing that some messages are missing correctly forwarded to graylog. They are missing only in the first hours, then after we can correctly see them. It is not a definite time it changes from the times.
I read what I was able to find on the community, the time of server, graylog server and user in graylog are all the same. The message does not contain timestamps in date format, in fact the arrival time is correctly taken for those that work.
Yes, that’s normal problem when timestamps are saved in future. You can find them, if you use absolute time frame selector and select future date. Check also if your devices have already setup correct timezone.
graylog was clustered, by shutting down one of the two frontend servers (graylog only, no elastic and no mongodb) the messages are immediately displayed correctly.